Tuesday, March 22, 2011

Home /Active Directory /AD /Microsoft /Migration /script /Windows /Windows 2008 R2 / Updating Group Membership “Dynamically”

Updating Group Membership “Dynamically”

I have created this script based on a question posted on the .  This script can be used to “dynamically” update the group member based of a LDAP attribute. 

In this example, I will be adding users who have the location attributes (l) populated with “SiteA” value into a security group called SiteA. 

The following command will remove the existing group members from SiteA group. 

dsget group "CN=SiteA,OU=TestOU,DC=Infralab, DC=local" -members | dsmod group "CN=SiteA,OU=TestOU,DC=Infralab, DC=local" –rmmbr

image

and the following command will filter all objects based on the location code (l=SiteA) and add them to the SiteA group. 

dsquery * -Filter "(l=SiteA)" | dsmod group "CN=SiteA,OU=TestOU,DC=Infralab, DC=local" -addmbr

image

You can use the same logic to copy group members from one group to another.  Here is an exmaple:

dsget group "CN=Group1,OU=TestOU,DC=Infralab, DC=local" -members | dsmod group "CN=Group2,OU=TestOU,DC=Infralab, DC=local" -addmbr

The above command will copy members from Group1 to Group2.


SS

Santhosh Sivarajan

Microsoft MVP · Identity & Cybersecurity Architect

Santhosh has 30+ years of hands-on enterprise experience in Identity and Access Management, Microsoft Entra ID, Active Directory, Microsoft 365 and Zero Trust architecture. He is the author of two books on Windows Server and security, and leads consulting, assessments and training at SAG Business Group.

2 comments:

Hello.

Is it possible to exclude users who belong the group already?

I would appreciate it shows me how to do it.

Regards

I am having a problem using the first of these commands, I am getting the "dsmod failed:You must specify at least one attribute to be modified."

here is my exact command issued via powershell

dsget group "CN=grp.sig.retail,OU=SignatureGroups,OU=GroupsAndUsers,DC=americanchartered,DC=com" -members | dsmod group "CN=grp.sig.retail,OU=SignatureGroups,OU=GroupsAndUsers,DC=americanchartered,DC=com" –rmmbr

that fails with the above error, running the first part before the pipe returns a list of the group members, as expected.

The CN is exatly the same as I "copy and pasted" it from the DSGET part of the command.

Any help would be greatly appreciated

Thanks Bob Sawyer

Post a Comment

Popular Posts
Workstation Trust Relationship Issue Issue: You receive the following error message, when you try to login to the domain.  The security database on the server does not have ... ADMT Service Account - Permission and Configuration The ADMT service account needs to have proper permission in source and target domains.  You don’t need to use 2 separate accounts.  You can ... My First Peek into Microsoft Exchange 2010 By Santhosh Sivarajan Before I really dive into Exchange 2010, I thought I would install and play with it first. I took some screen shots and notes during the ins... ObjectSID and Active Directory What is an objectSID in Active Directory? When a new object is created in Active Directory, Domain Controller assigns a unique value used ... AD Group Report - List Group Members in Active Directory–PowerShell Script Updated Script - http://portal.sivarajan.com/2011/10/search-ad-collect-local-admin-group.html Script #1 This script... Add Users to a Group–PowerShell Script Purpose – Add users to a group from an input file – PowerShell V2 Script.  Input file – Input file (Users.csv) contains samAccountName in... User Account Migration and Merging – Part I (ADMT) Part I - User Account Migration and Merging Using ADMT Part II - User Account Migration and Merging Using QMM pre-creating user account ... User Account Migration and Merging – Part II (Quest Migration Manager) Part I - User Account Migration and Merging Using ADMT Part II - User Account Migration and Merging Using QMM Pre-creating user account in... Delete Stale or Inactive Computer Accounts from Active Directory Here is an easy way to identify and delete inactive or stale computers in an Active Directory environment.  Using the dsquery command you c... Converting PowerShell (PS1) to EXE / Standalone Application As we know, there many applications available to convert a PowerShell file to a standalone executable file.  Based on my experience, PowerSh...